General

  • Target

    2024-06-20_685f406991f088d5849d939e56ae659b_gandcrab

  • Size

    75KB

  • MD5

    685f406991f088d5849d939e56ae659b

  • SHA1

    932896da4af452892f8cb7bea1126f6a57786ce3

  • SHA256

    56e5f04c9e004a41cde56a5e7c7632fe4a24b8a783473270b2dc8b5fd2397b03

  • SHA512

    1310db053fa465dc70e353b7b5c935b86c6fa4645cad679d0653e6d196843500e3d227020450df4668869e0ed1ff4f552a8ce09a07206fca84b7d8623632e25d

  • SSDEEP

    1536:v55u555555555pmgSeGDjtQhnwmmB0ybMqqU+2bbbAV2/S2mr3IdE8mne0Avu5rt:bMSjOnrmBTMqqDL2/mr3IdE8we0Avu55

Score
10/10

Malware Config

Extracted

Family

gandcrab

C2

http://gdcbghvjyqy7jclk.onion.top/

Signatures

  • Detects ransomware indicator 1 IoCs
  • GandCrab payload 1 IoCs
  • Gandcrab Payload 1 IoCs
  • Gandcrab family
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • 2024-06-20_685f406991f088d5849d939e56ae659b_gandcrab
    .exe windows:5 windows x86 arch:x86

    40306b615af659fc1f93cfb121cc38d9


    Headers

    Imports

    Sections